Certificate of Cloud Security Knowledge Flashcards
7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Certificate of Cloud Security Knowledge flashcards as text
Which technique BEST prevents unauthorized privilege escalation within a cloud management plane?
Answer: Implementing least-privilege IAM policies and enforcing multi-factor authentication
Least-privilege IAM policies limit what each identity can do, while MFA prevents stolen credentials from being used, together addressing the top management plane attack vectors.
What is 'serverless computing' and what is its PRIMARY security consideration?
Answer: Function-based execution where the provider manages runtime; primary concern shifts to application code and dependencies
In serverless, the provider manages all infrastructure and runtime, so security responsibility shifts almost entirely to the customer's application code, libraries, and function permissions.
Which cloud data security control ensures that data cannot be read even if an authorized cloud administrator is compromised?
Answer: Customer-managed encryption keys stored in a Hardware Security Module (HSM)
Customer-managed keys in HSMs mean the provider's administrators can never access plaintext because they don't possess the keys; only the customer controls decryption.
What is 'cloud workload protection platform' (CWPP) designed to protect?
Answer: Workloads running in cloud environments, including VMs, containers, and serverless functions
CWPPs secure the workloads themselves—virtual machines, containers, and functions—by providing runtime protection, vulnerability management, and behavioral monitoring.
In the CSA Guidance, what is the recommended approach to 'data classification' in cloud environments?
Answer: Classify data before moving it to the cloud and apply controls based on classification level
Organizations should classify data according to sensitivity before cloud migration and then apply appropriate security controls, encryption, and access policies based on each classification tier.
What does 'geo-residency' or 'data sovereignty' mean for cloud customers?
Answer: Legal requirements mandating that data be stored and processed within specific geographic boundaries
Data sovereignty laws in many jurisdictions require that certain types of data remain physically within national borders, which customers must verify their cloud provider can guarantee.
Which practice is MOST critical for maintaining cloud security posture over time as cloud environments evolve?
Answer: Implementing continuous monitoring and automated compliance scanning of cloud configurations
Cloud environments change constantly; continuous monitoring and automated scanning detect configuration drift, new vulnerabilities, and policy violations in real time.